SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security analyst in your organization receives an alert from Microsoft Defender XDR indicating that a user's device may be infected with ransomware. The analyst needs to immediately isolate the device from the network to prevent further spread. What should the analyst do?
⚠ Common exam trap
Test-takers frequently confuse identity-based controls (session revocation) with endpoint-based network containment, or they overcomplicate the response by thinking a SOAR playbook is required when Defender for Endpoint provides a one-click isolation action directly in the alert workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Microsoft Defender for Endpoint to initiate device isolation
Microsoft Defender for Endpoint includes a built-in device isolation capability that can be triggered directly from the Microsoft Defender XDR portal. This action immediately disconnects the device from all network communications (except the Defender service) to contain a confirmed ransomware infection, preventing lateral movement while allowing forensic analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Revoke the user's session in Microsoft Entra ID
Why it's wrong here
Revoking a user's session in Microsoft Entra ID terminates active sign-ins and invalidates refresh tokens, forcing reauthentication for cloud resources. While this action prevents further access to cloud applications and data, it does not isolate the compromised endpoint from the network or stop local malicious processes already running on the device. The threat actor could still be operating locally or laterally within the network from the compromised machine, making it ineffective for immediate device-level containment.
- ✓
Use Microsoft Defender for Endpoint to initiate device isolation
Why this is correct
Microsoft Defender for Endpoint provides robust capabilities for immediate incident response, including the ability to isolate a device from the network. Initiating device isolation restricts the compromised endpoint's communication to only essential Defender for Endpoint services, effectively containing the threat and preventing lateral movement or data exfiltration. This action allows security analysts to investigate the incident without further risk to the broader network, making it the most appropriate and immediate containment measure.
- ✗
Open Microsoft Sentinel and run a playbook
Why it's wrong here
While Microsoft Sentinel can orchestrate automated responses through playbooks, directly initiating device isolation via Defender for Endpoint is a more immediate and targeted action for containing a detected threat. A Sentinel playbook would typically trigger an action through Defender for Endpoint or another security tool, introducing a slight delay and requiring pre-configured automation. For critical, real-time containment of an active threat, direct action within the endpoint protection platform is generally preferred over an orchestrated, potentially delayed, playbook execution.
- ✗
Use Microsoft Intune to wipe the device
Why it's wrong here
Wiping a device using Microsoft Intune is a drastic measure that erases all user data, applications, and settings, restoring the device to its factory defaults. This action is typically reserved for lost or stolen devices, or when a device is deemed irrecoverably compromised and needs to be decommissioned. It is not an appropriate first response for an alert requiring immediate containment, as it destroys valuable forensic evidence needed for investigation and remediation, and is far more severe than simple isolation.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
XDR
XDR, or Extended Detection and Response, is a unified security platform that collects and correlates data across multiple security layers—endpoints, networks, servers, cloud workloads, and email—to improve threat detection and enable faster response.
Key term
Microsoft Defender XDR
Microsoft Defender XDR is a unified security platform that automatically correlates alerts from across an organization's endpoints, email, identities, and cloud apps to stop complex attacks.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.